Feds warn Gunra ransomware is exploiting known bugs to hit critical infrastructure

← Back to the feed

Feds warn Gunra ransomware is exploiting known bugs to hit critical infrastructure

The Register · 2 hours ago

US and South Korean cyber agencies, including CISA, the FBI, NSA and Secret Service, have issued a joint advisory warning that affiliates of the Gunra ransomware-as-a-service operation are exploiting known Fortinet vulnerabilities to break into critical infrastructure networks. Organisations in healthcare, financial services, government, professional services and other sectors have been targeted, with attackers gaining administrative access via internet-facing appliances before stealing data and encrypting systems in a double-extortion scheme.

Gunra first emerged in 2025 and has quickly evolved from a Windows-only threat borrowing code from the Conti ransomware operation into one with a Linux variant capable of running up to 100 encryption threads in parallel. The gang exploits CVE-2024-55591 and CVE-2025-24472, authentication bypass flaws in FortiOS and FortiProxy, and pressures victims via a Tor-based negotiation portal, typically giving them five to seven days to pay before leaking stolen data. Confirmed activity has been seen in Turkey, Taiwan, the US and South Korea, while the group's own leak site claims further victims in Brazil, Japan and Canada; agencies are urging organisations to patch known vulnerabilities, secure VPN and RDP access with multifactor authentication, segment networks, and maintain offline backups.

  • Gunra ransomware exploits known Fortinet flaws to breach critical infrastructure
  • US, South Korean agencies issue joint advisory urging urgent patching
  • Group uses double extortion, giving victims five to seven days to pay

Cybersecurity Technology

Read the full article at the source →